CVE-2024-6763
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/10/2024
Last modified:
10/07/2025
Description
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.<br />
<br />
The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI<br />
differs from the common browsers in how it handles a URI that would be <br />
considered invalid if fully validated against the RRC. Specifically HttpURI<br />
and the browser may differ on the value of the host extracted from an <br />
invalid URI and thus a combination of Jetty and a vulnerable browser may<br />
be vulnerable to a open redirect attack or to a SSRF attack if the URI <br />
is used after passing validation checks.
Impact
Base Score 3.x
3.70
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | 7.0.0 (including) | 9.4.57 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



